CVE-2025-27771: GHSL-2024-200_GHSL-2024-201: Zero click RCE in Uptrain - CVE-2025-27771, CVE-2025-27772
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27771?
CVE-2025-27771 has a risk score of 89, indicating a high severity vulnerability.
What is the nature of the vulnerability identified in CVE-2025-27771?
CVE-2025-27771 is a remote code execution vulnerability in the Uptrain dashboard due to inadequate authentication and an open CORS policy.
How do I fix CVE-2025-27771?
To fix CVE-2025-27771, ensure robust authentication mechanisms are implemented and configure the CORS policy to restrict access.
Who is affected by CVE-2025-27771?
Users of the Uptrain dashboard are at risk of exploitation from CVE-2025-27771.
When was CVE-2025-27771 published?
CVE-2025-27771 was published on August 8, 2026.